refalo

joined 2 years ago
[–] refalo@programming.dev 1 points 1 year ago* (last edited 1 year ago) (2 children)

if a hostile party has access to the handset, that encryption isn't particularly helpful

Things like Molly-FOSS might help better with that, keeping its database locked and encrypted at rest on its own separately from any OS encryption or security. Perhaps GrapheneOS or similar could be beneficial as well.

If you want something with not so many government ties, and maybe more decentralized, there is also SimpleX, Briar and Tox.

[–] refalo@programming.dev 3 points 1 year ago* (last edited 1 year ago)

It's also funded by the CIA. Although Signal is/was also indirectly funded by US Congress via OTF, and some claim that means the CIA is somehow involved too. Of course, computers, the internet and tor also had major US government funding, for what it's worth.

[–] refalo@programming.dev 5 points 1 year ago* (last edited 1 year ago) (1 children)

Because in a way, everything is political, to someone, whether you like it or not. Even mentioning the ACLU could imply there is some agenda behind what OP is doing.

[–] refalo@programming.dev 2 points 1 year ago* (last edited 1 year ago)

and some nut on HN posted a base64'd infohash of the torrent including the 7z password

[–] refalo@programming.dev 3 points 1 year ago* (last edited 1 year ago) (1 children)

Sample size of 1 is not indicative of anything though... several entire families I know were in it when I checked, even people that have been dead for decades, still had their name, address history, DOB, SSN and phone number.

Personally I consider this way bigger than previous ones because of how accessible the data is. I could never find the previous Experian one, but there's several sources for this one now, and seems to have a lot more information in it.

[–] refalo@programming.dev 2 points 1 year ago

Have you seen people?

[–] refalo@programming.dev 6 points 1 year ago* (last edited 1 year ago) (1 children)

Can't someone who has your SSN just thaw it themselves?

[–] refalo@programming.dev 1 points 1 year ago (1 children)

That work was not available when GrapheneOS was developed, and is not necessarily applicable to devices released after those findings... I still consider it a black box.

[–] refalo@programming.dev 16 points 1 year ago* (last edited 1 year ago) (4 children)

Not only that but it relies on the Pixel's black box "Titan" security chip, that google pinky-promised to open source but never did...

[–] refalo@programming.dev 3 points 2 years ago* (last edited 2 years ago)

Unfortunately neither GSM nor UMTS works in the US anymore. Only LTE/VoLTE and above is supported.

[–] refalo@programming.dev 3 points 2 years ago

Play App Signing is required for new apps.

Also now required is giving up your government identity document to google in order to keep publishing on the play store.

view more: ‹ prev next ›